Skip to content

CNTRLPLANE-3434: hypershift-install: use mounted CI pull secret in extract_hcp_cli - #82061

Merged
openshift-merge-bot[bot] merged 2 commits into
openshift:mainfrom
Nirshal:hypershift-install-fix-pull-secret
Jul 21, 2026
Merged

openshift-merge-bot[bot] merged 2 commits into
openshift:mainfrom
Nirshal:hypershift-install-fix-pull-secret

Conversation

@Nirshal

@Nirshal Nirshal commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does:
Switches extract_hcp_cli in hypershift-install-commands.sh from extracting the pull secret via oc extract secret/pull-secret -n openshift-config to using the already-mounted CI pull secret at /etc/ci-pull-credentials/.dockerconfigjson.

Why we need it:
Follow-up fix for #81877, which refactored the CLI extraction logic into a shared extract_hcp_cli function and added OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE support.

The openshift-config namespace does not exist on AKS clusters, causing extract_hcp_cli to fail when the HO release gate pipeline triggers AKS jobs with an image override.

The mounted CI pull secret is already used by hypershift install --pull-secret for Azure, GCP, and default cloud providers in the same script. This change aligns extract_hcp_cli with that existing pattern.

Background:
The inline extraction logic was originally introduced for HO_MULTI (bf81fdf, May 2024) and INSTALL_FROM_LATEST (3b34fa3, Nov 2024), both targeting OpenShift-only jobs where openshift-config always exists. The new OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE path runs across all platforms including AKS, exposing the issue for the first time.

Summary by CodeRabbit

  • Updated HyperShift CI installation to extract the hypershift CLI using the mounted /etc/ci-pull-credentials/.dockerconfigjson, fixing compatibility with AKS clusters where openshift-config may be unavailable.
  • Clarified that OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE is used by the HO release controller.

Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 17, 2026
@openshift-ci-robot

openshift-ci-robot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

@Nirshal: This pull request references CNTRLPLANE-3434 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the epic to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Follow-up fix for #81877.

extract_hcp_cli used oc extract secret/pull-secret -n openshift-config to authenticate with container registries when extracting the HyperShift CLI from a custom operator image. This fails on AKS clusters where the openshift-config namespace does not exist.

The same script already uses the mounted CI pull secret (/etc/ci-pull-credentials/.dockerconfigjson) for hypershift install --pull-secret on Azure, GCP, and default cloud providers. This change aligns extract_hcp_cli with that pattern.

Root cause: The extraction logic was originally introduced inline for HO_MULTI (bf81fdf, May 2024) and INSTALL_FROM_LATEST (3b34fa3, Nov 2024), both targeting OpenShift-only jobs. PR #81877 refactored it into a shared function and added OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, which is triggered by the HO release gate pipeline across all platforms including AKS.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from mgencur and sjenning July 17, 2026 08:36
@coderabbitai

coderabbitai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 12d242a8-82cb-498a-9d4e-ee2b4d58adbf

📥 Commits

Reviewing files that changed from the base of the PR and between c404467 and fb49ff7.

📒 Files selected for processing (1)
  • ci-operator/step-registry/hypershift/install/hypershift-install-ref.yaml

Walkthrough

Changes

HyperShift install updates

Layer / File(s) Summary
Update extraction and parameter documentation
ci-operator/step-registry/hypershift/install/hypershift-install-commands.sh, ci-operator/step-registry/hypershift/install/hypershift-install-ref.yaml
extract_hcp_cli uses the shared registry configuration for oc image extract, and OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE documentation notes its use by the HO release controller.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested labels: rehearsals-ack

Suggested reviewers: mgencur, sjenning

🚥 Pre-merge checks | ✅ 14 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (14 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: extract_hcp_cli now uses the mounted CI pull secret.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The PR only changes a shell script and a YAML doc; no Ginkgo tests or test titles are added or edited.
Test Structure And Quality ✅ Passed PR only changes a YAML doc string; no Ginkgo tests or cluster-interaction tests are modified, so the test-quality check is not applicable.
Microshift Test Compatibility ✅ Passed No new Ginkgo e2e tests were added; the only changed file is YAML documentation, so there are no MicroShift-incompatible APIs or features to review.
Single Node Openshift (Sno) Test Compatibility ✅ Passed The PR only changes YAML documentation text; no Ginkgo tests or SNO-relevant cluster assumptions were added or modified.
Topology-Aware Scheduling Compatibility ✅ Passed Only a shell helper and YAML docs changed; no manifests, replicas, node selectors, affinity, or scheduling logic were added.
Ote Binary Stdout Contract ✅ Passed PR only changes a step shell script and YAML docs; no OTE binary main/init/TestMain/suite code was touched, so stdout contract isn't affected.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PR only changes a shell helper and parameter docs; no Ginkgo test additions or IPv4/external-connectivity test code are present.
No-Weak-Crypto ✅ Passed Changed files only update a doc string and CLI extraction; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret/token comparisons were found.
Container-Privileges ✅ Passed PR only changes CLI extraction logic and a YAML doc string; no container/K8s manifest security fields were added or altered.
No-Sensitive-Data-In-Logs ✅ Passed The diff only updates a YAML documentation string; no logging statements or sensitive data exposure were added.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@Nirshal

Nirshal commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse periodic-ci-openshift-hypershift-release-4.19-periodics-e2e-aks periodic-ci-openshift-hypershift-main-periodics-e2e-aws-multi periodic-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-upgrade-minor periodic-ci-openshift-hypershift-main-periodics-e2e-aws-install-from-latest

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@csrwng

csrwng commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@csrwng: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@Nirshal

Nirshal commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse periodic-ci-openshift-hypershift-release-4.19-periodics-e2e-aks periodic-ci-openshift-hypershift-main-periodics-e2e-aws-multi periodic-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-upgrade-minor periodic-ci-openshift-hypershift-main-periodics-e2e-aws-install-from-latest

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: job(s): periodic-ci-openshift-hypershift-main-periodics-e2e-aws-multi, periodic-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator, periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-upgrade-minor, periodic-ci-openshift-hypershift-main-periodics-e2e-aws-install-from-latest either don't exist or were not found to be affected, and cannot be rehearsed

@Nirshal

Nirshal commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

/retest

@Nirshal

Nirshal commented Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Test Failure Analysis: e2e-azure-v2-self-managed — Flake (unrelated to PR)

Failed Test

[sig-hypershift][Jira:Hypershift][Feature:ControlPlaneWorkloads] Control Plane Workloads
  No crashing pods — hosted-cluster-config-operator [It] should have no crashing pods

Result: 425 Passed | 1 Failed | 1 Pending | 536 Skipped

Root Cause

The hosted-cluster-config-operator pod (hosted-cluster-config-operator-cf4b6cf8f-nzxkp) restarted 2 times during hosted cluster bootstrap due to transient management cluster API server unavailability:

Error: failed to detect management cluster capabilities: the server is currently unable to handle the request

Timeline (namespace clusters-public-8e81b0b246):

Time (UTC) Event
08:46:05 Pod created
08:46:08 Init container availability-prober completed
~08:46:09 1st start → crash (API server 503)
08:47:41 2nd start → crash at 08:48:03 (same error, exit code 1)
08:48:13 3rd start → stable (running at dump time)

The test asserts restartCount <= 0; it was 2. All other 25+ control plane workloads (kube-apiserver, etcd, kube-controller-manager, kube-scheduler, etc.) passed the same "no crashing pods" check with 0 restarts.

Proof This Is Unrelated to PR Changes

The hypershift-install step log (set -eux trace) shows the PR's new code paths were never executed in this job:

+ [[ -n '' ]]       # MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE — empty
+ [[ -n '' ]]       # OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE — empty
+ [[ false == true ]]  # HO_MULTI — false
+ [[ false == true ]]  # INSTALL_FROM_LATEST — false

All three override flags evaluated to empty/false → extract_hcp_cli() was never called → HCP_CLI remained bin/hypershift (the default step container binary). The hypershift install command executed identically to what it would have been without this PR. The pull secret source (--pull-secret=/etc/ci-pull-credentials/.dockerconfigjson) was also unchanged.

Secondary Post-Step Failures

  • dump-management-cluster: management cluster API still unreachable after guest teardown
  • destroy-management-cluster: ImagePullBackOff for CI image (manifest unknown in quay-proxy) — pod never started, timed out after 1h

Both are infrastructure issues unrelated to the test or the PR.


Analysis generated from Prow job artifacts

@Nirshal

Nirshal commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Test Failure Analysis: e2e-azure-v2-self-managed (2nd run) — Infrastructure flake, tests PASSED

Build: 2079230338550206464

All tests passed

The test phase completed successfully:

Step e2e-azure-v2-self-managed-tests succeeded after 1h15m6s
Step phase test succeeded after 1h15m6s

Failure is in post-step cleanup only

The job failed in the post phase (teardown), not during tests:

  1. destroy-guests (1h8m): Azure ResourceGroupDeletionTimeout — Azure could not delete resource group autoscaling-56c02dfa17-nsg-* within the allowed time (HTTP 409 Conflict)
  2. dump-management-cluster (1h timeout): ImagePullBackOff — CI step image sha256:ce4bea79862b9590efb11020992d9cf6989c0138a175710ee6323cd8d231b6ab not found in quay-proxy.ci.openshift.org or quay.io mirrors (manifest unknown). Pod never started.
  3. destroy-management-cluster (9m): Azure resource group deletion failed with HTTP stream cancellation error

Relationship to PR

None. The hypershift-install step succeeded. Tests passed. The failures are:

  • Azure API-side resource group deletion timeouts (Azure infrastructure issue)
  • CI image registry returning "manifest unknown" for the step container image (CI infrastructure issue)

Both are completely outside the scope of this PR's changes.


Analysis from Prow job artifacts

@Nirshal

Nirshal commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

🔍 Test Failure Analysis — 2nd run (2079230338550206464)

Job: rehearse-82061-pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed
Result: All tests passed. Job failed exclusively in post-phase cleanup steps (infrastructure issues).


Evidence

1. All tests passed ✅

From build log line 101:

Step e2e-azure-v2-self-managed-tests succeeded after 1h15m6s.

2. The PR's step (hypershift-install) succeeded ✅

From build log line 93:

Step e2e-azure-v2-self-managed-hypershift-install succeeded after 2m15s.

3. Job failure reason is pod_pending, not a test failure

From build log line 491:

Reporting job state 'failed' with reason '...pod_pending'

A CI step pod failed to start — no test assertion failed.

4. Complete step-by-step timeline

Phase Step Duration Result
pre ipi-install-rbac 9s ✅
pre create-management-cluster 20m39s ✅
pre hypershift-azure-setup-private-link 57s ✅
pre hypershift-install (modified by this PR) 2m15s ✅
pre hypershift-resolve-nodepool-releases 35s ✅
pre hypershift-azure-create-selfmanaged-guests 17m28s ✅
test tests 1h15m6s ✅ All tests passed
post dump 16m32s ✅
post hypershift-debug 10s ✅
post hypershift-k8sgpt 26s ✅
post destroy-guests 1h8m26s ❌ Azure ResourceGroupDeletionTimeout
post dump-management-cluster 1h0m22s ❌ ImagePullBackOff (manifest unknown)
post destroy-management-cluster 9m25s ❌ Azure HTTP/2 stream cancelled

Every pre and test phase step succeeded. Only 3 post-phase cleanup steps failed.

5. Root causes of the 3 post-phase failures

destroy-guests — Azure ARM API returned HTTP 409 ResourceGroupDeletionTimeout:

{
  "code": "ResourceGroupDeletionTimeout",
  "message": "Deletion of resource group 'autoscaling-56c02dfa17-nsg-autoscaling-56c02dfa1-xm7ht'
              did not finish within the allowed time..."
}

This is an Azure-side timeout deleting the NSG resource group for the autoscaling guest cluster.

dump-management-cluster — CI step image sha256:ce4bea79... doesn't exist in the registry:

manifest unknown in quay-proxy.ci.openshift.org/openshift/ci
manifest unknown in quay.io/openshift/ci (mirror)

The pod was pending for 1h with 260× Back-off pulling image events before being killed. This image is the step container for dump-management-cluster, resolved by ci-operator at runtime — it is not referenced or modified by this PR.

destroy-management-cluster — Azure HTTP/2 stream error during NSG resource group deletion:

stream error: stream ID 89; CANCEL; received from peer

6. PR changes are provably not involved

  • The SHA ce4bea79... (the failing image) does not appear anywhere in the PR diff:
    $ git diff main -- ci-operator/step-registry/hypershift/install/ | grep -c "ce4bea79"
    0
    
  • This PR only modifies hypershift-install-commands.sh and hypershift-install-ref.yaml.
  • The failing steps (destroy-guests, dump-management-cluster, destroy-management-cluster) are completely separate step-registry components.
  • All three failures are caused by external infrastructure: Azure ARM API timeouts and CI image registry unavailability.

Conclusion

This is a pure infrastructure flake. The job's test phase completed with all tests passing. The failure is entirely in post-phase cleanup due to Azure resource group deletion timeouts and a missing CI step image in quay-proxy. None of these issues are related to the PR's changes to pull secret handling in extract_hcp_cli.

Recommendation: retry.

@Nirshal

Nirshal commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse ack

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot openshift-merge-bot Bot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Jul 21, 2026
@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 21, 2026
@openshift-ci

openshift-ci Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bryan-cox, Nirshal

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 21, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit a7c6ed7 into openshift:main Jul 21, 2026
16 of 17 checks passed
fracappa pushed a commit to fracappa/release that referenced this pull request Jul 22, 2026
…tract_hcp_cli (openshift#82061)

* fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli

Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>

* docs(hypershift-install): add HO release controller note to env doc

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
amogh-redhat pushed a commit to amogh-redhat/release that referenced this pull request Aug 5, 2026
…tract_hcp_cli (openshift#82061)

* fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli

Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>

* docs(hypershift-install): add HO release controller note to env doc

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
TimurMP pushed a commit to TimurMP/release that referenced this pull request Sep 5, 2026
…tract_hcp_cli (openshift#82061)

* fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli

Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>

* docs(hypershift-install): add HO release controller note to env doc

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. rehearsals-ack Signifies that rehearsal jobs have been acknowledged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants